psa, 37C3 

To folks going to 37C3: Don't visit the talk about SMTP smuggling. The authors of it have not done responsible disclosure to postfix about a security vulnerability with some configurations (default configurations, in fact). Let them have empty seats.

re: psa, 37C3 

@kescher Like seriously, I'd respect them more if they wouldn't notify anyone, instead of only notifying the corpos…

re: psa, 37C3 

@ar @kescher Is there somewhere I can read more about this?

· · Web · 1 · 0 · 1

re: psa, 37C3 

@kescher @ar The "oh we didn't realize we had to look further after Cisco told us it's fine" seems extremely disingenuous given that the research specifically identifies postfix as a large affected implementations (and given that they seemed to disagree with Cisco's assessment anyway)

Sign in to participate in the conversation
Pixietown

Small server part of the pixie.town infrastructure. Registration is closed.